Vulnerability CVE-2003-1299


Published: 2003-12-31   Modified: 2012-02-12

Description:
Directory traversal vulnerability in Baby FTP Server 1.2, and possibly other versions before May 31, 2003 allows remote authenticated users to list arbitrary directories and possibly read files via "..." (triple dot) manipulations to the CWD command.

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Pablo software solutions -> Baby ftp server 

 References:
http://packetstormsecurity.org/0305-exploits/baby.txt
http://www.pablosoftwaresolutions.com/html/baby_ftp_server.html
http://www.securityfocus.com/bid/7749

Copyright 2024, cxsecurity.com

 

Back to Top